HAZOP, LOPA and SIL: Process Hazard Analysis in Practice
Have Questions ?
HAZOP, LOPA and SIL: Process Hazard Analysis in Practice - SF-HLS-PEA27
| Code | Date | Time | Duration | Location | Currency | Early Bird Fee Per Person |
|---|---|---|---|---|---|---|
| SF-HLS-PEA27 | 11 - 15 Oct 2027 | 10 AM CST | 5 Days - 4 Hours / Day |
Online |
USD |
4000 |
Need this for a group? We deliver the same course in-house — face-to-face at your location or online — tailored to your assets and team level. Contact info@peassociations.com.
Boost your team's skills and your budget! Enjoy group discounts for collaborative learning. Send an inquiry to info@peassociations.com.
HAZOP, LOPA and SIL: Process Hazard Analysis in Practice
Applied process hazard analysis, covering HAZID and HAZOP methodology and facilitation, layer of protection analysis, independent protection layer qualification, safety integrity level determination and verification, the functional safety lifecycle, action management and study quality assurance.
Description
Process hazard analysis determines what a facility is protected against and how strongly. The studies produce the safeguards list, the shutdown logic, the relief requirements and the safety integrity levels that govern instrumented protection for the life of the plant. When they are done well they produce a facility whose protection is proportionate to its risk. When they are done poorly they produce either a plant with gaps in its protection or one loaded with instrumented functions that are expensive to maintain and deliver little risk reduction.
This training covers the three linked methods in the order they are applied. HAZID is covered as the early study that identifies hazards at concept and design stage. HAZOP is developed in full: node selection, design intent definition, parameter and guide word application, cause and consequence development, safeguard identification and recommendation writing, together with the facilitation practice that determines whether a study produces useful output. Layer of protection analysis follows, covering scenario selection, initiating event frequency estimation, independent protection layer qualification and the calculation of residual risk against tolerability criteria. Safety integrity level determination and verification are then covered, including architecture, probability of failure on demand, proof test interval and the functional safety lifecycle requirements that apply once a SIL has been assigned. The training closes with action management, study quality assurance and revalidation.
The quality of a HAZOP depends more on facilitation and team composition than on methodology. The method itself is simple: take a node, state its design intent, apply parameters and guide words, and work through causes, consequences and safeguards. What makes the difference is whether the team includes people who know how the plant actually operates, whether the facilitator keeps the study at the right level of detail, whether consequences are followed through to their real severity rather than stopped at the first alarm, and whether recommendations are specific enough to be closed out meaningfully.
Layer of protection analysis exists because HAZOP identifies scenarios but does not quantify them. A HAZOP team can list five safeguards for a scenario without establishing whether any of them are independent, effective and available, or whether five is more than enough or not enough. LOPA imposes discipline: each claimed protection layer must be independent of the initiating event and of every other layer, specific to the scenario, auditable and reliable enough to justify the credit taken. Layers routinely fail these tests when examined properly.
Safety integrity levels then quantify what the instrumented protection must achieve. A SIL is not a rating of importance; it is a required risk reduction factor that determines architecture, component selection, proof test interval and design discipline. Assigning SILs too high creates instrumented functions that are expensive to build and maintain and that generate spurious trips. Assigning them too low leaves risk unaddressed. Both errors are common, and both originate in weak LOPA work upstream.
Finally, hazard studies have a poor record of follow-through. Recommendations are raised, assigned, deferred and eventually closed with weak justification, and the risk reduction assumed in the study is never actually delivered. Action management is as important to the outcome as the study itself.
By the end of this training, participants will be able to:
- Select the appropriate hazard study method for a given project stage and objective
- Prepare and facilitate a HAZOP including node definition, documentation and team composition
- Apply parameters and guide words systematically and develop causes, consequences and safeguards
- Write recommendations that are specific, assignable and verifiable
- Select scenarios for LOPA and estimate initiating event frequencies from recognised data sources
- Qualify independent protection layers and reject claimed layers that do not meet the criteria
- Calculate residual risk and determine the required risk reduction factor for a scenario
- Determine safety integrity levels and verify achieved SIL against architecture and proof test interval
- Apply functional safety lifecycle requirements from SIL assignment through operation and testing
- Manage study actions and conduct study revalidation on operating facilities
The training is built around executing the methods rather than describing them. Participants work through HAZOP nodes on real facility drawings, developing causes, consequences, safeguards and recommendations as a team, with facilitation practice and review of the resulting worksheets. LOPA scenarios are then developed from those HAZOP outputs, with initiating event frequencies assigned, protection layers qualified or rejected, and required risk reduction calculated. SIL determination and verification calculations follow on the same scenarios. Study worksheets from completed projects are examined and critiqued, including weak examples, and incident cases where a hazard study failed to identify a scenario are analysed.
Organisations sending participants to this training will:
- Improve the quality and consistency of hazard studies conducted across projects and operating assets
- Reduce over-specification of safety instrumented functions and the lifetime cost that follows from it
- Identify protection gaps that weak studies would have left unaddressed
- Improve action close-out so that the risk reduction assumed in studies is actually delivered
- Strengthen compliance with functional safety standards and regulatory expectations
- Build internal facilitation capability and reduce dependence on external study leaders
Participants will:
- Facilitate or contribute effectively to HAZOP and HAZID studies
- Apply LOPA rigorously and challenge protection layers that do not qualify
- Determine and verify safety integrity levels with a defensible basis
- Recognise weak hazard study work and say why it is weak
- Understand the functional safety obligations that follow a SIL assignment
- Build a competence recognised across process industries and jurisdictions
- Process safety engineers and practitioners
- Process, facilities and design engineers taking part in hazard studies
- Operations engineers and supervisors participating in HAZOP teams
- Control, instrumentation and functional safety engineers
- Project engineers responsible for study scheduling and action close-out
- Maintenance and integrity engineers responsible for safety critical equipment
- Technical managers accountable for facility risk
Module 1 - Process Hazard Analysis Framework
- Purpose and scope of process hazard analysis
- Study types and their appropriate project stage:
HAZID, HAZOP, what-if, FMEA, bow-tie, QRA
- Regulatory and standard framework: IEC 61511, IEC
61508, national requirements
- Risk concepts: frequency, consequence, tolerability,
ALARP
- Risk matrices and their construction and misuse
- The barrier model and layers of protection
- Relationship between hazard studies, relief design
and shutdown design
- Study planning, scheduling and resourcing across a
project
Module 2 - HAZID and Early Stage Studies
- HAZID purpose and timing
- Hazard checklists and their application
- External and environmental hazards
- Layout, spacing and escalation hazards
- Constructability, operability and maintainability
hazards
- Concept selection support and inherently safer design
review
- HAZID documentation and action handling
- Transition from HAZID findings to detailed design
Module 3 - HAZOP Methodology
- HAZOP principle and its systematic basis
- Study preparation: drawings, documents, data, and
their required maturity
- Node selection and boundary definition
- Design intent statement and its importance
- Parameters and guide words and their combination
- Cause development and credibility
- Consequence development and following through to real
severity
- Safeguard identification and its distinction from a
recommendation
- Recording conventions and worksheet structure
- Batch, procedural and human factors HAZOP variants
- HAZOP on existing facilities against HAZOP on new
design
Module 4 - HAZOP Facilitation and Team Practice
- Facilitator role, skills and preparation
- Team composition and required disciplines
- Scribe function and recording quality
- Managing pace, depth and scope creep
- Handling dominant participants and disengaged
participants
- Keeping the study at the right level of detail
- Deciding when to stop developing a scenario
- Writing recommendations that are specific and
assignable
- Managing disagreement and unresolved items
- Study reporting, review and sign-off
- Common failures in HAZOP execution
Module 5 - Layer of Protection Analysis: Principles
- LOPA purpose and its relationship to HAZOP output
- Scenario selection and definition for LOPA
- Single cause single consequence discipline
- Consequence severity categorisation
- Tolerable frequency targets and their derivation
- Initiating event identification and frequency
estimation
- Data sources for initiating event frequency
- Enabling conditions and conditional modifiers
- Ignition probability, occupancy and fatality
probability
- LOPA documentation and worksheet structure
Module 6 - Independent Protection Layers
- Criteria for an independent protection layer:
independence, specificity, dependability, auditability
- Basic process control system as a protection layer
and its credit limits
- Alarms with operator response and the conditions for
taking credit
- Safety instrumented functions as protection layers
- Pressure relief devices as protection layers
- Physical and passive protection: dykes, blast walls,
fireproofing
- Mechanical design and inherently safer features
- Emergency response and its limited credit
- Common cause failure between claimed layers
- Testing claimed layers and rejecting those that do
not qualify
- Calculating residual risk and the required risk
reduction
Module 7 - Safety Integrity Level Determination
- Safety instrumented function definition and boundary
- Safety integrity level definitions and risk reduction
factors
- SIL determination methods: LOPA, risk graph, matrix,
quantitative
- Consistency between methods and their comparative
rigour
- Demand mode and continuous mode operation
- SIL assignment documentation and safety requirements
specification
- Consequences of over-assignment and under-assignment
- Multiple functions protecting the same scenario
- SIL determination for existing facilities
- Common errors in SIL determination
Module 8 - SIL Verification and Design
- Probability of failure on demand and its calculation
- Architecture: one out of one, one out of two, two out
of three and other configurations
- Hardware fault tolerance and architectural
constraints
- Safe failure fraction and diagnostic coverage
- Failure rate data sources and their quality
- Proof test interval and its effect on achieved SIL
- Proof test coverage and imperfect testing
- Common cause failure factor and beta factor
estimation
- Systematic capability and prior use justification
- Spurious trip rate and its consideration in design
- Verification calculation and documentation
Module 9 - Functional Safety Lifecycle
- IEC 61511 lifecycle phases and their requirements
- Safety requirements specification content
- Design, engineering and factory acceptance testing
- Installation, commissioning and validation
- Operation and maintenance requirements for safety
instrumented systems
- Proof testing execution, documentation and interval
management
- Bypass and override management and its control
- Demand recording and performance monitoring against
assumptions
- Management of change for safety instrumented
functions
- Functional safety assessment stages
- Competence requirements across the lifecycle
- Decommissioning of safety instrumented functions
Module 10 - Action Management, Quality and
Revalidation
- Recommendation tracking and close-out discipline
- Assessing proposed close-out against the original
intent
- Risk acceptance and deferral decisions and their
governance
- Study quality assurance and peer review
- Auditing hazard study output for completeness and
depth
- Revalidation triggers and intervals for operating
facilities
- Managing legacy studies of unknown quality
- Integrating hazard study output with the safeguards
register
- Linking studies to operating procedures, training and maintenance
- Learning from incidents where the hazard study missed
the scenario
Upon successful completion of this training course, delegates will be awarded an official Certificate of Completion issued by the Petroleum Engineers Association (PEA), an ISO 9001:2015 certified training organization. The certificate carries 10 Credits and formally records the total learning hours completed.
Each certificate is signed by the Course Facilitator and the CEO of the Petroleum Engineers Association, and serves as verifiable proof of professional training that delegates can present to employers and professional bodies worldwide.
This course is led by a process safety and hazard analysis specialist with more than 20 years in the oil and gas industry, built on running the studies that decide which protection a facility actually needs.
He currently holds process safety leadership responsibility with a major operator managing hazard analysis and safety integrity programmes across production and processing facilities, covering HAZOP facilitation, layer of protection analysis and safety integrity level determination — the disciplines that translate hazard identification into the right level of protection. Earlier in his career he served as a process safety engineer on major facility developments, leading HAZID and HAZOP studies and functional safety lifecycle implementation on some of the industry's most safety-critical projects. Across two decades he has facilitated numerous hazard studies that shaped how facilities are protected and operated.
That operating background shapes how he teaches. Delegates learn not only how HAZOP, LOPA and SIL studies are meant to be run, but how they hold up in practice — where HAZOP facilitation actually breaks down, why independent protection layers get wrongly qualified, what makes safety integrity level determination defensible, how the functional safety lifecycle is managed beyond the initial study, and how project and operations teams handle action management and study quality assurance together. Every module is anchored in real hazard study data, decisions and lessons from facilities where protection philosophy was tested.
His subject coverage spans the full process hazard analysis chain: HAZID and HAZOP methodology and facilitation, layer of protection analysis, independent protection layer qualification, safety integrity level determination and verification, the functional safety lifecycle, action management and study quality assurance.
He has delivered process hazard analysis training for many years across the Middle East, North Africa and Southeast Asia, working with mixed groups of process safety engineers, process engineers and technical management at every level of experience. He is an active contributor to industry forums on process safety and functional safety.
His approach is practical, discussion-led and grounded in real hazard analysis experience — not the textbook.
Frequently Asked Questions
All course bookings made through PEA are strictly non-refundable. By registering for a course, you acknowledge and accept that all fees are payable in full and are not subject to refund under any circumstances, including changes in personal or professional commitments or partial attendance.
PEA reserves the right to make reasonable adjustments to course content, trainers, or schedules where necessary, without entitling delegates to a refund. Comprehensive details of each course — including objectives, target audience, and content — are clearly outlined before enrolment, and it is the responsibility of the delegate to ensure the course's suitability prior to booking.
For any inquiries related to cancellations or bookings, please contact our support team, who will be happy to assist you.